- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: checkpoint Firewall audit for configuration ch...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
checkpoint Firewall audit for configuration change
Hi ,
How to do audit for Firewall configuration changes done through cli or GUI .
Suppose if any firewall engineer perform changes I would to like know who logged in to firewall and what changes has been done .
Regards,
Vaibhav
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
You have to enable Audit logs on WebUI to send management server, please check the attached snip.
You can check Audit logs in SmartConsole --> Logs & Monitor --> New Tab -->Click on Audit Logs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This would be your first port of call: Logs & Monitor > New Tab > Audit...
GUI being SmartDashboard vs Web UI?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Normally commands in clish are recorded in the messages file, I don't know about the WebUI.
When you use a TacAcs server though this will record the actions done per user per system, sorry I do not know to what level.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Maarten ,
Thanks for the response .
Correct ,from smart console we can see only firewall rules changes , admin operation in smart console .
I am more interested to find out changes done on GAIA from CLI or WEBGUI .
Regards,
Vaibhav
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
By default, OS audit logs are sent to /var/log/messages
You can also redirect Gaia logging to another file, as described here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
You have to enable Audit logs on WebUI to send management server, please check the attached snip.
You can check Audit logs in SmartConsole --> Logs & Monitor --> New Tab -->Click on Audit Logs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi ,
I have enabled Audit logs on WebUI and its working as expected . Thanks very much !!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Yatiraj,
We have the same issue. We can't see the audit logs in Smart Console from the gateways.
The recommended config we already implemented but we still don't see the audit logs from the gateways from the Smart Console audit logs tab.
Do we need to do any more step to make this work?
From gateway: System Management > System Logging > Send audit logs to management server upon successful configuration is ticked
Hoping for anyone's help.
Thanks.
